W.C.A. Wijngaards
9d2e0f1c02
- Unit test for CVE-2026-42944.
2026-05-20 12:34:16 +02:00
W.C.A. Wijngaards
b46ff5c18e
- Unit test for CVE-2026-33278.
2026-05-20 12:32:43 +02:00
W.C.A. Wijngaards
f597105800
- Tag for 1.25.1 release, it contains the security fixes on 1.25.0.
...
the code repository continues with in addition the previous fixes,
for 1.25.2.
2026-05-20 11:31:53 +02:00
W.C.A. Wijngaards
3692517a41
Merge branch 'branch-1.25.1'
2026-05-20 11:19:56 +02:00
W.C.A. Wijngaards
75b6dba593
- Fix CVE-2026-44608, Use after free and crash in RPZ code. Thanks
...
to Qifan Zhang, Palo Alto Networks, for the report.
release-1.25.1
2026-05-20 10:22:52 +02:00
W.C.A. Wijngaards
138fb48eac
Changelog entry.
...
- Fix CVE-2026-44390, Unbounded name compression in certain cases
causes degradation of service. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-05-20 10:22:10 +02:00
W.C.A. Wijngaards
dae7a37974
- Fix CVE-2026-44390, Unbounded name compression in certain cases
...
causes degradation of service. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-05-20 10:21:26 +02:00
W.C.A. Wijngaards
8ae4b4545d
- Fix CVE-2026-42960, Possible cache poisoning attack while following
...
delegation. Thanks to TaoFei Guo from Peking University, Yang Luo
and JianJun Chen, Tsinghua University, for the report.
2026-05-20 10:20:45 +02:00
W.C.A. Wijngaards
c343fff3a4
- Fix CVE-2026-42923, Degradation of service with unbounded NSEC3
...
hash calculations. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
2026-05-20 10:20:02 +02:00
W.C.A. Wijngaards
a794c87578
- Fix CVE-2026-42534, Jostle logic bypass degrades resolution
...
performance. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
2026-05-20 10:19:08 +02:00
W.C.A. Wijngaards
ef5ca84360
- Fix CVE-2026-41292, Parsing a long list of incoming EDNS options
...
degrades performance. Thanks to GitHub user 'N0zoM1z0', also Qifan
Zhang from Palo Alto Networks, for the report.
2026-05-20 10:18:23 +02:00
W.C.A. Wijngaards
8d8fa42266
- Fix CVE-2026-40622, "Ghost domain name" variant. Thanks to Qifan
...
Zhang, Palo Alto Networks, for the report.
2026-05-20 10:16:18 +02:00
W.C.A. Wijngaards
a587535c5d
- Fix CVE-2026-32792, Packet of death with DNSCrypt. Thanks to Andrew
...
Griffiths from 'calif.io' for the report.
2026-05-20 10:15:30 +02:00
W.C.A. Wijngaards
94d5babaee
- Fix CVE-2026-42959, Crash during DNSSEC validation of malicious
...
content. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-20 10:14:32 +02:00
W.C.A. Wijngaards
fe946ba4e9
- Fix CVE-2026-42944, Heap overflow and crash with multiple nsid,
...
cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-05-20 10:13:55 +02:00
W.C.A. Wijngaards
6a31e470f8
- Fix CVE-2026-33278, Possible remote code execution during DNSSEC
...
validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-20 10:13:08 +02:00
W.C.A. Wijngaards
e577695aeb
Set version to 1.25.1 for release.
2026-05-20 10:11:15 +02:00
W.C.A. Wijngaards
a58bd6cb1e
- Fix for mixed class referrals, the resolver uses the query
...
class. Thanks to Xin Wang and Jiajia Liu, Northwestern
Polytechnical University, for the report.
2026-05-18 16:42:39 +02:00
W.C.A. Wijngaards
4bad944ae4
- Fix DNSKEY size calculation for noncanonical RSA DNSKEYs
...
with leading zeroes for n. Thanks to Xin Wang and Jiajia Liu,
Northwestern Polytechnical University, for the report.
2026-05-15 16:22:59 +02:00
W.C.A. Wijngaards
594182f109
- Fix DNSSEC validation with libnettle for noncanonical RSA
...
DNSKEYs with leading zeroes for n. Thanks to Xin Wang and
Jiajia Liu, Northwestern Polytechnical University, for
the report.
2026-05-15 16:20:52 +02:00
W.C.A. Wijngaards
53c261cb33
- Fix for allocation-failure hardening of rrset cache wildcard
...
storage and canonical NSEC owner replacement. Thanks to Xin
Wang and Jiajia Liu, Northwestern Polytechnical University,
for the report.
2026-05-15 16:00:58 +02:00
W.C.A. Wijngaards
8703d9a5be
- Fix that for dns64 answers, the AAAA query is checked to be
...
DNSSEC validated, when DNSSEC is enabled. This improves
the RFC6147 conformance of Unbound. Thanks to Xin Wang
and Jiajia Liu, Northwestern Polytechnical University, for
the report. In addition, thanks to Qifan Zhang, Palo Alto
Networks, for reporting it.
2026-05-15 15:43:18 +02:00
W.C.A. Wijngaards
aa9f1e68ff
- Fix val_find_DS for robustness, to check the result of
...
packet_rrset_copy_region before using it. Thanks to Xin Wang
and Jiajia Liu, Northwestern Polytechnical University, for
the report.
2026-05-15 14:27:18 +02:00
W.C.A. Wijngaards
84a4f556b1
Merge branch 'master' of github.com:NLnetLabs/unbound
2026-05-15 08:42:40 +02:00
W.C.A. Wijngaards
5b166dbf0a
- Fix man page entry for so-sndbuf, it is for responses sent out.
2026-05-15 08:42:27 +02:00
Yorgos Thessalonikefs
9e2233b821
- Fix another comment for EDNS fallback buffer size.
2026-05-14 13:11:17 +02:00
Yorgos Thessalonikefs
13716dc8be
- Fix comment and verbose logging for EDNS fallback buffer size.
2026-05-11 20:39:38 +02:00
W.C.A. Wijngaards
8ada1bd88d
- Fix to relax assertions after the TTL 0 handling change.
...
This relaxes an assertion in cachedb (it fails instead),
and for packet_rrset_copy_region.
2026-05-08 10:09:41 +02:00
W.C.A. Wijngaards
9c80bb9fb0
- Fix to clean up log ids after a failure to start a worker thread.
2026-05-07 14:42:29 +02:00
W.C.A. Wijngaards
33e2863862
- Fix for Heap Out-of-Bounds Write via size_t-to-int Truncation
...
in setup_if() - outside_network_create(). This fixes that
large values for num_ports do not overflow and create
invalid references after integer truncation. Thanks
to Karnakar Reddy (@karnakarreddi) for the report.
2026-05-07 14:40:48 +02:00
W.C.A. Wijngaards
027e23a11d
- iana portlist updated.
2026-05-01 11:25:49 +02:00
W.C.A. Wijngaards
62e8db1c6a
- Fix windows 64bit build for libssp dependency.
2026-04-29 15:06:09 +02:00
W.C.A. Wijngaards
581b2f31bc
- tag for 1.25.0. The code repository continues with 1.25.1 in
...
development.
2026-04-29 12:10:23 +02:00
W.C.A. Wijngaards
25fe602024
- For #1441 : Fix type of ipv6 addr struct.
release-1.25.0
2026-04-23 09:37:30 +02:00
W.C.A. Wijngaards
df0e86de49
Changelog entry for #1441 .
...
- Merge #1441 : Fix buffer overrun in
doq_repinfo_retrieve_localaddr().
2026-04-23 09:35:44 +02:00
Fothsid and GitHub
e49b550cf3
Fix buffer overrun in doq_repinfo_retrieve_localaddr() ( #1441 )
2026-04-23 09:35:23 +02:00
W.C.A. Wijngaards
07c96792f2
- Fix doxygen comment syntax.
release-1.25.0rc1
2026-04-21 13:44:55 +02:00
W.C.A. Wijngaards
84ab430e11
- Set version number to 1.25.0 of code repository.
2026-04-21 13:27:55 +02:00
W.C.A. Wijngaards
53499e4a88
- Fix handling of wildcard CNAMEs in the chain of trust.
...
An improper wildcard in the chain of trust would send
the retries to the wrong upstream. Also it could label
the step in the chain of trust as secure, when it was not.
Thanks to Qifan Zhang, Palo Alto Networks for the report.
2026-04-21 13:24:40 +02:00
W.C.A. Wijngaards
8a25a97687
- Fix that a DNAME with an unsigned CNAME is checked for
...
the correct match. This stops that for certain zone
configurations an unchecked unsigned CNAME could get
secure status. Thanks to Qifan Zhang, Palo Alto Networks
for the report.
2026-04-21 13:19:13 +02:00
W.C.A. Wijngaards
c112bcf2fd
- Fix that signatures are not allowed with revoked dnskeys.
...
Thanks to Qifan Zhang, Palo Alto Networks for the report.
2026-04-21 13:07:34 +02:00
W.C.A. Wijngaards
9de549c498
- Fix that upstream TLS connections are not reused as TLS
...
connections for a different name, at the same IP. This
checks that the tls name is correct when reusing the
upstream connections. Thanks to TaoFei Guo from Peking
University and JianJun Chen from Tsinghua University for
the report.
2026-04-21 11:59:05 +02:00
W.C.A. Wijngaards
84c645e7b3
- Fix for missing bounds check for decompressing dnames
...
for downloaded authority zones. This fixes that the server
could end up with malformed zone content after receiving
truncated packet contents from an AXFR. In addition, the
domain names in the SOA rdata are checked before the
authority code picks up the zone serial.
Thanks to Halil Oktay for the report.
2026-04-21 10:32:37 +02:00
W.C.A. Wijngaards
197a425c7d
- Fix for iterator RCODE handling of YXDOMAIN. This fixes
...
that the server only accepts YXDOMAIN answers that contain
a DNAME record. This stops bad answers, and checks that
the authoritative server gives correct replies.
Thanks to Qifan Zhang, Palo Alto Networks for the report.
2026-04-21 10:09:02 +02:00
W.C.A. Wijngaards
311054728d
- Fix EDNS extended RCODE reflection. This fixes that
...
the server does not echo extended rcode values after class
chaos queries. Thanks to Qifan Zhang, Palo Alto Networks
for the report.
2026-04-21 09:58:19 +02:00
W.C.A. Wijngaards
6d74856212
- Fix for the Jiggle Attack. The server is fixed to answer
...
with errors for error cases, and does not stay silent.
In addition, the error replies do not contain parts of the
incoming query. This is more conformant, stops reflection
and stops it as a covert channel. Thanks to Yuqi Qiu and
Xiang Li, Nankai University (AOSP Lab) for the report.
In addition, thanks to Qifan Zhang, Palo Alto Networks, for
noting the fingerprinting possibility, that is also fixed
with this.
2026-04-21 09:54:17 +02:00
W.C.A. Wijngaards
d489e6027e
- Add test case for malformed SVCB records. Thanks to
...
Qifan Zhang, Palo Alto Networks for the additional test.
2026-04-21 09:41:53 +02:00
W.C.A. Wijngaards
e1d146d6b0
- Fix test with https zone for libressl.
2026-04-20 16:10:33 +02:00
W.C.A. Wijngaards
eb2fe8df8d
- Fix unused variable warning when compiled without ssl.
2026-04-20 12:24:55 +02:00
W.C.A. Wijngaards
86a8be75f0
- Fix compile warnings for thread setname routine, and test compile.
2026-04-20 12:24:28 +02:00